| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
22-Oct-2009, 04:58 PM
#1 |
| AVG 8 will not update, google redirecting HJT included Hello, I have been having some trouble lately especially with Internet Explorer. I am able to use the internet, but often times I am redirected to sites, especially when using google. I use AVG free edition, but it says both my anti-virus and anti-spyware databases are outdated. When i try to update, I get a message saying, "The connection with the update server has failed." It says to go to avg.com, but this is impossible because I can't go to any anti-virus site. If I try to go to an antivirus site, I get a message saying that I can't connect to the internet with a button that says diagnose connection problems. Or I am taken to a google search of what I just entered in the address bar. Here are some of the sites I am being redirected to: www.ave99.com, www.everydayhealth.com, www.amspec-05.com Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:20:15 PM, on 10/22/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\windows\System32\smss.exe C:\windows\system32\winlogon.exe C:\windows\system32\services.exe C:\windows\system32\lsass.exe C:\windows\system32\svchost.exe C:\windows\System32\svchost.exe C:\windows\system32\spoolsv.exe C:\windows\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\windows\system32\rundll32.exe C:\windows\system32\RUNDLL32.EXE C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\SkyGolf\SkyCaddie Desktop\CaddieSyncLauncher.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\windows\system32\nvsvc32.exe C:\windows\system32\PnkBstrA.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\windows\system32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgui.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\windows\sySTEM32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\windows\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\windows\system32\sdra64.exe, O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll O2 - BHO: TBSB00982 - {DA3D342F-FF20-4E31-9E82-22334155730C} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll O3 - Toolbar: Ant.com Toolbar - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [PromoReg] C:\windows\Temp\_ex-08.exe O4 - HKLM\..\Run: [11142184] C:\Documents and Settings\All Users\Application Data\11142184\11142184.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [CaddieSyncLauncher] C:\Program Files\SkyGolf\SkyCaddie Desktop\CaddieSyncLauncher.exe O4 - HKLM\..\Run: [Internet Connection Wizard Setup Tool] C:\Program Files\Internet Explorer\Connection Wizard\icwsetup.exe O4 - HKLM\..\Run: [13617826] C:\DOCUME~1\ALLUSE~1\APPLIC~1\13617826\13617826.exe O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - Startup: ikowin32.exe O4 - Global Startup: icwsetup.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: PUFLITE - http://deniseleach.point2agent.com/O...ol/PUFLITE.CAB O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com...reqlab_srl.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD39/JS...ws-i586-jc.cab O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Futuremark SystemInfo) - http://www.yougamers.com/systeminfo/FMSI.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: C:\WINDOWS\system32\avgrsstx.dll O20 - Winlogon Notify: avgrsstarter - C:\windows\SYSTEM32\avgrsstx.dll O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: IY - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IY.exe (file missing) O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe O23 - Service: PnkBstrA (pnkbstra) - Unknown owner - C:\windows\system32\PnkBstrA.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- End of file - 7979 bytes |
| |
|
23-Oct-2009, 10:19 PM
#2 |
| Hello there Welcome to the Tech Support Guy forums.My name is NeonFx. I'll be glad to help you with your computer problems. Logs can take some time to research, so please be patient with me. Please note the following:
Step 1 Download OTS to your Desktop
Please attach the log in your next post. To do so click on the blue "Reply" button or "Go Advanced" and click on the "Manage Attachments" button To ensure that I get all the information this log will need to be attached. If it is too large to attach then upload it to Mediafire and post the sharing link. Step 2 Download RootRepeal from one of the following locations and save it to your desktop: Link 1
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.
__________________ Please post the final results, good or bad. Let me know if you won't be responding any longer. Please don't send me requests for help. Use the forums instead. |
|
26-Oct-2009, 08:31 PM
#4 |
| ComboFix should never be used without supervision by someone trained in its use. It does a whole lot more than just scan and remove files and can very easily cripple a system. But seeing as you already ran it, could you please attach C:\ComboFix.txt to your next reply so that I can see what it removed? Also, please go to C:\QooBox and attach any ComboFix#.txt along with Combofix-quarantined-files.txt Also, please do the following: STEP 1 Run OTS
STEP 2 Run OTS again and click on the Quick Scan button at the top. Attach the results of this scan in your next reply.
__________________ Please post the final results, good or bad. Let me know if you won't be responding any longer. Please don't send me requests for help. Use the forums instead. |
|
28-Oct-2009, 09:40 PM
#5 |
| I can't get the combofix file because i uninstalled the program. But, AVG updated so I guess that is a good sign. AVG detected about 25 threats upon opening and most of them were under C:\Program Files\Internet Explorer. I'm going to wait before I use AVG. I attached the quick scan as OTS.txt Here is what I got after the restart: All Processes Killed [Win32 Services - Safe List] Unable to stop service ddnsfilter! Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ddnsfilter deleted successfully. DllUnregisterServer procedure not found in C:\Program Files\DDnsFilter\DDnsFilter.dll C:\Program Files\DDnsFilter\DDnsFilter.dll NOT unregistered. C:\Program Files\DDnsFilter\DDnsFilter.dll moved successfully. Service IY stopped successfully! Service IY deleted successfully! File not found. [Driver Services - Safe List] Service d1f4ce5b stopped successfully! Service d1f4ce5b deleted successfully! C:\windows\System32\drivers\d1f4ce5b.sys moved successfully. Unable to stop service filter! Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\filter deleted successfully. C:\windows\System32\drivers\Filter.sys moved successfully. [Registry - Safe List] Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\11142184 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\13617826 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\PromoReg deleted successfully. C:\windows\Temp\_ex-08.exe moved successfully. Registry key HKEY_USERS\S-1-5-21-3594272691-42644781-3159205762-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\Run not found. Starting removal of ActiveX control {1E54D648-B804-468d-BC78-4AFFED8E262E} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1E54D648-B804-468d-BC78-4AFFED8E262E}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E54D648-B804-468d-BC78-4AFFED8E262E}\ deleted successfully. Starting removal of ActiveX control {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D1E7CBDA-E60E-4970-A01C-37301EF7BF98}\Contains\Files\ not found. C:\WINDOWS\Downloaded Program Files\FMSI.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D1E7CBDA-E60E-4970-A01C-37301EF7BF98}\ deleted successfully. Starting removal of ActiveX control PUFLITE Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\PUFLITE\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\PUFLITE\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\Te mp\_ex-08.exe deleted successfully. File C:\WINDOWS\Temp\_ex-08.exe not found. [Empty Temp Folders] User: All Users User: Davis ->Temp folder emptied: 219478626 bytes ->Temporary Internet Files folder emptied: 276536738 bytes ->FireFox cache emptied: 34097728 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 229376 bytes ->Java cache emptied: 4042 bytes User: Denise ->Temp folder emptied: 17664144 bytes ->Temporary Internet Files folder emptied: 129148212 bytes ->Java cache emptied: 1842431 bytes ->FireFox cache emptied: 68787070 bytes User: Griffin ->Temp folder emptied: 89973515 bytes ->Temporary Internet Files folder emptied: 448831414 bytes ->Java cache emptied: 2993059 bytes ->FireFox cache emptied: 4211491 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 10080038 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 6104140 bytes User: TEMP ->Temp folder emptied: 573843 bytes %systemdrive% .tmp files removed: 0 bytes C:\windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP folder deleted successfully. C:\windows\msdownld.tmp folder deleted successfully. %systemroot% .tmp files removed: 155648 bytes %systemroot%\System32 .tmp files removed: 2577 bytes Windows Temp folder emptied: 173636 bytes RecycleBin emptied: 7507184 bytes Total Files Cleaned = 1257.32 mb < End of fix log > OTS by OldTimer - Version 3.0.23.1 fix logfile created on 10282009_194403 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
|
28-Oct-2009, 11:14 PM
#6 |
| Alright, let's run a couple scanners to make sure we got everything. STEP 1 Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly. STEP 2 I also want to run an online scanner. This will take a while but it's well worth it as it will often find stuff that all other scanners will miss. The online scanner uses Java, so I will need you to download and install the latest version for that. Please go here to download the installer: http://java.com/en/download/index.jsp STEP 3 Using Internet Explorer or Firefox, visit Kaspersky Online Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take quite a long time to download.
__________________ Please post the final results, good or bad. Let me know if you won't be responding any longer. Please don't send me requests for help. Use the forums instead. |
|
31-Oct-2009, 01:48 AM
#8 |
| You can find the logs for MalwareBytes by clicking on the "Logs" tab. Could you post the one that has detected items on it for me? I want to see what it found so that I may determine if there is anything else we need to do. Also, hows the computer running?
__________________ Please post the final results, good or bad. Let me know if you won't be responding any longer. Please don't send me requests for help. Use the forums instead. |
|
31-Oct-2009, 11:34 AM
#9 |
| Ok I got it. And I think the computer is running normally now. Malwarebytes' Anti-Malware 1.41 Database version: 3063 Windows 5.1.2600 Service Pack 3 10/30/2009 7:27:49 PM mbam-log-2009-10-30 (19-27-49).txt Scan type: Quick Scan Objects scanned: 115268 Time elapsed: 3 minute(s), 54 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 10 Registry Values Infected: 2 Registry Data Items Infected: 3 Folders Infected: 3 Files Infected: 10 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{191 27ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43b f8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494 e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\syst emsecurity2009 (Rogue.TotalSecurity) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DbgMgr (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SfX (Rootkit.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ddnsfilter (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RList (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files\DDnsFilter (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Documents and Settings\Denise\Start Menu\Programs\Total Security (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lowsec (Stolen.data) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Denise\Start Menu\Programs\Total Security\Total Security 2009.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\Documents and Settings\Denise\Desktop\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\Denise\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\Denise\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully. C:\RECYCLER\ADAPT_Installer.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\0535251103110107106.yux (KoobFace.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\010112010146120114.xe (KoobFace.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\0101120101464949.xe (KoobFace.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\0101120101465653.xe (KoobFace.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\prxid93ps.dat (Malware.Trace) -> Quarantined and deleted successfully. |
|
31-Oct-2009, 03:00 PM
#10 |
| Alright. Before I give you my closing speech please do the following: STEP 1 Run OTS
__________________ Please post the final results, good or bad. Let me know if you won't be responding any longer. Please don't send me requests for help. Use the forums instead. |
|
03-Nov-2009, 10:28 PM
#11 |
| All Processes Killed [Custom Items] :clearrestorepoints Restorepoints cleared and new one set! [Empty Temp Folders] User: All Users User: Davis ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->FireFox cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes User: Denise ->Temp folder emptied: 88508524 bytes ->Temporary Internet Files folder emptied: 36150439 bytes ->Java cache emptied: 25626594 bytes ->FireFox cache emptied: 0 bytes User: Griffin ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: TEMP ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 29795853 bytes RecycleBin emptied: 2812312 bytes Total Files Cleaned = 174.52 mb < End of fix log > OTS by OldTimer - Version 3.0.23.1 fix logfile created on 11032009_212428 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
|
04-Nov-2009, 01:52 AM
#12 |
| Excellent. Let's cleanup. STEP 1 To clean up OldTimer's tools, along with a few others, do the following:
STEP 2 Remove any other tools or files we used by right-clicking on them or any folders they created, hold down the Shift key, and select "Delete" by clicking on it. This will delete the files without sending them to the RecycleBin. You can also uninstall the other programs (HijackThis or MalwareBytes if we used them) by going to Start > Control Panel > Add/Remove programs (Programs and Features in Vista/7) All Clean Congratulations!, Microsoft Windows Update Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Install the updates immediately if they are found. To update Windows Go to Start > All Programs > Windows Update To update Office Open up any Office program. Go to Help > Check for Updates Download and Install a HOSTS File A HOSTS file is a big list of bad web sites. The list has a specific format, a specific name, (name is just HOSTS with no file extension), and a specific location. Your machine always looks at that file in that location before connecting to a web site to verify the address. So the HOSTS listing can be used to "short circuit" a request to a bad website by giving it the address of your own machine. Download BlockList Pro's HOSTS Manager HERE
You can use this manager to handle your HOSTS file download, edits, and most any other HOSTS issue. If you have a separate party firewall or Winpatrol, you may have to give permissions at various times to Unlock the present default HOSTS file and install the new one. Install WinPatrol Download it HERE You can find information about how WinPatrol works HERE Other Software Updates It is very important to update the other software on your computer to patch up any security issues you may have. Go HERE to scan your computer for any out of date software. In particular make sure you download the updates for Java and Adobe as these are subject to many security vulnerabilities. Setting up Automatic Updates So that it is not necessary to have to remember to update your computer regularly (something very important to securing your system), automatic updates should be configured on your computer. Microsoft has guides for XP and Vista on how to do this. Read further information HERE on how to prevent Malware infections and keep yourself clean. Feel free to mark this thread as "Solved" by clicking on the button at the top of this page. If you need anything else let me know.
__________________ Please post the final results, good or bad. Let me know if you won't be responding any longer. Please don't send me requests for help. Use the forums instead. |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 04:29 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

